CVE-2025-30731 is a low-severity vulnerability affecting Oracle Applications Technology Stack versions 12.2.3 through 12.2.14, specifically within the Configuration component of Oracle E-Business Suite. An unauthenticated attacker with infrastructure logon can achieve unauthorized read and limited update/insert/delete access to data, but successful exploitation requires human interaction from a non-attacker. The CVSS 3.1 Base Score is 3.6, indicating low confidentiality and integrity impacts due to high attack complexity and user interaction requirements. There is currently no public exploit code, active exploitation, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.2.3, <= 12.2.14CPE matchmatch criteria | cpe:2.3:a:oracle:applications_technology_stack:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.